---
id: CVE-2025-27463
title: >-
  [This CNA information record relates to multiple CVEs; the text explains which
  aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers
  expose various facilities to userspace
summary: >-
  [This CNA information record relates to multiple CVEs; the text explains which
  aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers
  expose various facilities to userspace. Several of these have no security
  descriptor,…
severity: none
cwe:
  - CWE-276
published: '2026-07-09'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-27463'
references:
  - url: 'https://xenbits.xen.org/xsa/advisory-468.html'
    label: security@xen.org
tags:
  - nvd
epss: 0.00158
epssPercentile: 0.04283
ingestedAt: '2026-09-29T19:44:04.104Z'
---

## Overview

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
